ExBB is reported prone to a script injection vulnerability. It is reported that nested BBCode is not sufficiently sanitized of malicious script content. Injected code may be rendered in the Web browser of a user who views vulnerable areas of the site. This would occur in the security context of the site hosting ExBB. ExBB 1.9.1 is reported vulnerable, however, other versions may be affected as well.
ExBB is reported prone to a script injection vulnerability. It is reported that nested BBCode is not sufficiently sanitized of malicious script content. Injected code may be rendered in the Web browser of a user who views vulnerable areas of the site. This would occur in the security context of the site hosting ExBB. ExBB 1.9.1 is reported vulnerable, however, other versions may be affected as well.